Avyqo

Security policy

Last updated 5 October 2026

Report vulnerabilities privately to security@avyqo.app. A machine-readable version of this policy is at /.well-known/security.txt.

Scope

  • avyqo.app and its subdomains
  • oroxia.io and the Oroxia web app

How to report

Please include a clear description of the issue, the steps to reproduce it, the affected URL or component, and the impact you believe it has. Screenshots or a short proof of concept help us move faster. Writing from a Proton Mail address keeps your report end-to-end encrypted in transit to us.

What you can expect

  • An acknowledgement within three working days.
  • An initial assessment and expected timeline within ten working days.
  • Updates as we work on a fix, and credit when it ships, if you would like it.

Good-faith research

We will not pursue action against researchers who act in good faith and within these guidelines:

  • Only test against accounts you own or have explicit permission to use.
  • Do not access, change or delete other people’s data. If you encounter it, stop and tell us.
  • Do not run denial-of-service, spam or social-engineering tests, or physical attacks.
  • Give us reasonable time to fix the issue before sharing it publicly.

Out of scope

  • Reports from automated scanners without a demonstrated impact.
  • Missing best-practice headers or settings with no practical exploit.
  • Issues that require a compromised device or physical access.

We do not currently run a paid bug bounty, but we are grateful for every responsible report.